Earlier quoted context omitted.
When you get the prompt to input the code, just choose "Did not get a verification code" and it will fall back to SMS. See: https://blog.elcomsoft.com/wp-content/uploads/2016/03/apple_...
Interesting, I did not realize that.
SMS is not 2FA-secure
371–379 of 379 posts
Re: SMS is not 2FA-secure
#372My understanding is that you don't even need to do a SIM swap, because the SS7 signaling system is insecure. SIM Swap is likely the easiest way as wage-slave employees are quite pliable to bribes[0]. But if you want to be even more anonymous, you can apparently re-route texts remotely [1]. 0: https://www.nbcbayarea.com/news/local/mans-1m-life-savings-s... 1: https://www.kaspersky.com/blog/ss7-hacked/25529/ I thought…
Does that mean an authoritarian government can read the location and sms of a number from foreign country without any cooperation from the carrier? Scary thought
Re: SMS is not 2FA-secure
#373Earlier quoted context omitted.
I think we just need to be prepared for these sorts of things. Travel with cash, your debit card, and one or two credit cards. If you can afford it, have a backup SIM (Twilio sells SIM cards for about $3 and the cost to keep them activated is $1/mo, and nothing more if you don't use it [0]). Use a Twilio or Google Voice number that you don't use for anything else for 2FA or account recovery for services that require…
It's about convenience. 99% of the people will take convenience over security. Changing behaviour is difficult
Re: SMS is not 2FA-secure
#374Earlier quoted context omitted.
How would this work exactly?
The clerk has to use some kind of online system to connect the new sim to the customers phone number. The system would obviously require the clerk to authenticate himself and could require him to enter the passport number or other document ID he checked to verify the customers identity. If later it turns out this was a sim swapping attack you can verify if the clerk entered a valid document ID. He can’t do that witho…
I wasn't sure how would you solve the problem of verifying the ID card without showing the previously recorded number to the clerk. But simply requiring to every time just punch in the ID (and maybe scan the whole card to check the photo later) could work - if the system only returns a big OK or BAD signal.
Currently here, in Hungary, the clerks just photocopy the IDs though. And there was a big scandal a few years ago (in connection to the ISIL/ISIS attacks in EU) about some groups obtaining hundreds of thousands of SIMs for just a few names.
Re: SMS is not 2FA-secure
#375Earlier quoted context omitted.
You can get a federal ID. It's called a passport card. It costs $65. The US also has the REAL ID[0] standard that requires IDs to meet minimum standards in order to be accepted by the federal government. If carriers just required a REAL ID compliant ID in order to get a new SIM, and actually checked it via the chip or magnetic strip, I think we'd be good. [0] https://www.dhs.gov/real-id
You can get a federal ID. It's called a passport card. It costs $65. Which is usually a really crappy idea when you want to save a few bucks compared to a real passport. They're umpteen stories of heartbreak and hurt, by people not being allowed to board an international flight, or a cruise which stops at destinations not covered by a passport card. They're also those that thought it's a great idea to get them for th…
I'm not saying use it for international travel, I'm saying use it as an ID? Literally any American citizen can get an ID card for $65 that is accepted everywhere someone asks you for ID.
If we started taking things a bit more seriously, we could also get that fee down by subsidizing it.
Re: SMS is not 2FA-secure
#376Re: SMS is not 2FA-secure
#377I thought this was going to be one of the otherwise-plaintext black and white web pages with NO. centered in the middle, but interestingly it's actual research, and a nice read (even if nothing new) at that.
Re: SMS is not 2FA-secure
#378Now I only need to find out on which ones of my 200+ accounts this feature is enabled… Honestly, it would be easier for me if the EU just made it illegal, forcing services to disable it for me.
Why? It's not "secure" but it's more secure than nothing. The paper mentions some websites that claim to use SMS 2FA, but actually use SMS as a single factor for password resey. While that's really bad I think the solution is to fix those broken implementations not to stop using SMS 2FA everywhere in favor of using nothing.
Re: SMS is not 2FA-secure
#379Earlier quoted context omitted.
I've implemented something like this at Dontport. There are few work arounds but again security isn't something that's on top of traditional carrier because it's a problem with a small set of people
Nice product! https://dontport.com/ Do you know if something like this exists in europe?